pub async fn verify<F, Fut, E>(
cfg: &UrlTokenConfig,
token: &str,
binding: &Binding<'_>,
now_ms: i64,
read_epoch: F,
) -> Result<Result<(), TokenRejected>, E>Expand description
§9.4 verification for a serving path: UrlTokenConfig::precheck,
then Prechecked::check_binding, then exactly one read_epoch
call and the epoch comparison. read_epoch never runs when an
earlier phase fails — the stored-epoch read is the last step
(SPEC-HTTP-OBJECTS §6). A public repository ignores the result; that
choice belongs to the serving caller (SPEC-HTTP-OBJECTS §3 step 5).
§Errors
The outer Err is read_epoch’s own error — an infrastructure
failure, never confused with a rejection (SPEC-HTTP-OBJECTS §3: a
store failure is a 503, not a fabricated not_found). The inner
Err is the uniform TokenRejected.